Signal
New Windows zero-days expose BitLocker bypass and privilege escalation flaws
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-05-13 16:16 UTCUpdated 2026-05-13 16:37 UTC
rss
cveexploitswindowsbitlockerprivilege_escalationsecurity_advisories
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
An anonymous security researcher known as Nightmare-Eclipse has released proof-of-concept exploits for two unpatched Microsoft Windows vulnerabilities called YellowKey and GreenPlasma.
Score total
1.01
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- The zero-days were disclosed just after Microsoft's latest Patch Tuesday, highlighting ongoing vulnerabilities.
- Public release of proof-of-concept code raises the risk of active exploitation.
- Physical access requirements for YellowKey still pose a significant threat to device security.
Why it matters
- BitLocker is a key security feature protecting encrypted drives; bypassing it exposes sensitive data.
- Privilege escalation flaws like GreenPlasma enable attackers to gain full system control.
- The exploits were released shortly after Microsoft's security updates, increasing risk before patches.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- Nightmare-Eclipse released two Windows zero-days named YellowKey and GreenPlasma.
- YellowKey is a BitLocker bypass that grants unrestricted shell access with physical access and a USB key sequence.
- GreenPlasma is a privilege escalation flaw that provides SYSTEM access.
How sources frame it
- The Register Security: neutral
All evidence
All evidence
Windows BitLocker zero-day gives access to protected drives, PoC released
bleepingcomputer_all · bleepingcomputer.com · 2026-05-13 16:37 UTC
Mystery Microsoft bug leaker keeps the zero-days coming
The Register Security · theregister.com · 2026-05-13 16:16 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- bleepingcomputer_all (1)
- The Register Security (1)
Top origin domains (this list)
- bleepingcomputer.com (1)
- theregister.com (1)